Weaknesses of type CWE-122

3,195 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2024-20745HIGHZDI-CAN-22671: Adobe Premiere Pro AVI File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-21596MEDIUMJunos OS and Junos OS Evolved: A specific BGP UPDATE message will cause a crash in the backup Routing Engine in NSR-enabled devicesEPSS 0.5%CVE-2026-32945HIGHPJSIP is vulnerable to Heap-based Buffer Overflow through DNS parserEPSS 0.5%CVE-2020-15198MEDIUMHeap buffer overflow in TensorflowEPSS 0.5%CVE-2025-0870MEDIUMAxiomatic Bento4 Ap4DataBuffer.h GetData heap-based overflowEPSS 0.5%CVE-2024-2212HIGHInteger wraparounds, under-allocations, and heap buffer overflows in Eclipse ThreadX xQueueCreate() and xQueueCreateSet()EPSS 0.5%CVE-2025-2754MEDIUMOpen Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection heap-based overflowEPSS 0.5%CVE-2023-4692HIGHGrub2: out-of-bounds write at fs/ntfs.c may lead to unsigned code executionEPSS 0.5%CVE-2025-32717HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-50176HIGHDirectX Graphics Kernel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-10921HIGHGIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-10934HIGHGIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-22660HIGHA heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record typEPSS 0.5%CVE-2026-42975HIGHWindows Bluetooth Port Driver Remote Code ExecutionEPSS 0.5%CVE-2024-50571MEDIUMA heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7EPSS 0.5%CVE-2024-56406HIGHPerl is vulnerable to a heap buffer overflow when transliterating non-ASCII bytesEPSS 0.5%CVE-2022-42403HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.5%CVE-2026-62816HIGHWindows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-62823HIGHWindows DHCP Server Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-42904CRITICALWindows TCP/IP Elevation of Privilege VulnerabilityEPSS 0.5%